
Simple File List Security & Risk Analysis
wordpress.org/plugins/simple-file-listSimple File List is a powerful WordPress file manager. Publish a file library anywhere on your site — let users browse, download, upload, share and pl …
Is Simple File List Safe to Use in 2026?
Mostly Safe
Score 76/100Simple File List is generally safe to use. 19 past CVEs were resolved.
The "simple-file-list" plugin v6.1.18 exhibits a mixed security posture. While it demonstrates good practices in SQL query handling and output escaping, several significant concerns arise from its attack surface and vulnerability history. The presence of seven unprotected AJAX handlers creates a substantial entry point for attackers, as any of these could potentially be exploited without proper authentication checks. Furthermore, the detection of dangerous functions like `shell_exec` and `exec` warrants careful review, as these can be leveraged for remote code execution if not handled with extreme caution and robust sanitization.
The plugin's historical vulnerability landscape is a major red flag. With 15 known CVEs, including two critical and three high-severity vulnerabilities, there's a clear pattern of past security weaknesses. The common vulnerability types, such as Missing Authorization, Cross-Site Scripting, and Path Traversal, indicate recurring issues with input validation and access control. The existence of a currently unpatched CVE, even if the last reported vulnerability is in the future, suggests that active threats might still be present or that the reporting date is erroneous and the unpatched CVE is a present danger.
In conclusion, while the plugin shows some positive aspects like secure SQL usage, the high number of unprotected entry points, the use of dangerous functions, and a history rife with severe vulnerabilities point to a plugin that requires significant attention. Users should be cautious, and thorough security audits are recommended before deploying this plugin in production environments. The ongoing trend of past vulnerabilities suggests a potential for future exploits.
Key Concerns
- 7 unprotected AJAX handlers
- Use of dangerous functions (shell_exec, exec)
- 1 currently unpatched CVE
- 2 critical historical CVEs
- 3 high historical CVEs
- Common vulnerability: Missing Authorization
- Common vulnerability: Cross-site Scripting
- Common vulnerability: Path Traversal
Simple File List Security Vulnerabilities
CVEs by Year
Severity Breakdown
19 total CVEs
Simple File List <= 6.3.8 - Reflected Cross-Site Scripting
Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute
Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter
Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
Simple File List <= 6.1.15 - Authenticated (Subscriber+) Arbitrary File Download
Simple File List <= 6.3.7 - Missing Authorization
Simple File List <= 6.1.14 - Unauthenticated Arbitrary File Download
Simple File List <= 6.1.13 - Missing Authorization to Unauthenticated Minor Settings Update
Simple File List <= 6.1.11 - Reflected Cross-Site Scripting
Simple File List <= 6.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
Simple File List <= 6.1.9 - Unauthenticated Arbitrary File Deletion
Simple File List <= 6.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
Simple File List <= 4.4.11 - Reflected Cross-Site Scripting
Simple File List <= 4.4.12 - Cross-Site Request Forgery to Page Creation
Simple File List <= 4.4.11 - Reflected Cross-Site Scripting
Simple File List < 4.2.3 - Remote Code Execution
Simple File List <= 4.2.7 - Arbitrary File Deletion
Simple File List <= 3.2.4 - Arbitrary File Deletion
Simple File List <= 3.2.7 - Arbitrary File Download
Simple File List Release Timeline
Simple File List Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple File List Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Simple File List Maintenance & Trust
Maintenance Signals
Community Trust
Simple File List Alternatives
Filr – Secure document library
filr-protection
Easily Create a Secure Document Library with Filr
Document Library Lite
document-library-lite
Create a WordPress document library to manage, search and download files.
Shared Files – File Upload & Download Manager
shared-files
File management plugin featuring file upload, download manager, statistics and download log.
Secure Client Portal and Private File Sharing Plugin – User Private Files
user-private-files
WordPress secure client portal plugin with file sharing and document manager. Upload, manage and share documents with users safely.
ERI File Library
eri-file-library
Easily upload, manage, and track downloads of your shared files
Simple File List Developer Profile
4 plugins · 3K total installs
How We Detect Simple File List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-file-list/css/sfl-styles.css/wp-content/plugins/simple-file-list/css/sfl-tiles.css/wp-content/plugins/simple-file-list/css/sfl-flex.css/wp-content/plugins/simple-file-list/css/sfl-admin.css/wp-content/plugins/simple-file-list/js/sfl-scripts.js/wp-content/plugins/simple-file-list/uploader/js/sfl-upload.js/wp-content/plugins/simple-file-list/js/sfl-scripts.js/wp-content/plugins/simple-file-list/uploader/js/sfl-upload.js/wp-content/plugins/simple-file-list/css/sfl-styles.css?ver=/wp-content/plugins/simple-file-list/css/sfl-tiles.css?ver=/wp-content/plugins/simple-file-list/css/sfl-flex.css?ver=/wp-content/plugins/simple-file-list/css/sfl-admin.css?ver=/wp-content/plugins/simple-file-list/js/sfl-scripts.js?ver=/wp-content/plugins/simple-file-list/uploader/js/sfl-upload.js?ver=HTML / DOM Fingerprints
ee-sfl-wrappersfl-main-wrappersfl-tablesfl-tilessfl-flexsfl-upload-formsfl-admin-sectionsfl-file-row+1 more<!-- Simple File List by Element Engage --><!-- Simple File List Pro by Element Engage -->data-ee-sfl-iddata-ee-sfl-typedata-ee-sfl-actioneesfl_vars/wp-json/simplefilelist/v1/upload/wp-json/simplefilelist/v1/edit[eeSFL][eeSFLS]